CVE-2026-97735: Itflow
High severity, CVSS 8.0. EPSS: 0.3% chance of exploitation in the next 30 days.
ITFlow before 26.08 allows SVG attachments in the ticket email parser (cron/ticket_email_parser.php) for email messages that may arrive over SMTP from arbitrary senders.
Affected products
- Itflow Itflow: before 26.08 (fixed in 26.08)
Published 2026-09-25. Last modified 2026-09-30.